¡¾Îó²îͨ¸æ¡¿pgAdmin 4 Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î(CVE-2025-13780)
Ðû²¼Ê±¼ä 2025-12-17Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | pgAdmin 4 Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î | ||
CVE ID | CVE-2025-13780 | ||
Îó²îÀàÐÍ | RCE | ·¢Ã÷ʱ¼ä | 2025-12-17 |
Îó²îÆÀ·Ö | 9.1 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | µÍ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
pgAdminÊÇÒ»¸öÓÃÓÚÖÎÀíºÍ¿ª·¢PostgreSQLÊý¾Ý¿âµÄ¿ªÔ´Í¼Ðλ¯¹¤¾ß¡£¡£¡£¡£¡£ËüÌṩÁËÒ»¸öÓû§ÓѺõĽçÃæ£¬£¬£¬£¬£¬£¬ÓÃÓÚÖ´ÐÐSQLÅÌÎÊ¡¢ÖÎÀíÊý¾Ý¿â¹¤¾ß¡¢Éó²éÊý¾Ý¿â¹¤¾ßµÄ½á¹¹¡¢ÌìÉú±¨±íºÍ±¸·Ý/»Ö¸´Êý¾Ý¿âµÈ²Ù×÷¡£¡£¡£¡£¡£pgAdminÖ§³Ö¶àÖÖ²Ù×÷ϵͳ£¬£¬£¬£¬£¬£¬°üÀ¨Windows¡¢macOSºÍLinux£¬£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÒÔͨ¹ýWebä¯ÀÀÆ÷»á¼û£¬£¬£¬£¬£¬£¬±ãÓÚÔ¶³ÌÖÎÀí¡£¡£¡£¡£¡£ËüÆÕ±éÓ¦ÓÃÓÚÊý¾Ý¿âÖÎÀíÔ±¡¢¿ª·¢Ö°Ô±ºÍÊý¾ÝÆÊÎöʦÖУ¬£¬£¬£¬£¬£¬Ö§³ÖPostgreSQLµÄËùÓй¦Ð§²¢¼ò»¯ÁËÊý¾Ý¿âÖÎÀíʹÃü¡£¡£¡£¡£¡£
2025Äê12ÔÂ17ÈÕ£¬£¬£¬£¬£¬£¬c7c7ÓéÀÖÆ½Ì¨¼¯ÍÅVSRC¼à²âµ½pgAdmin 4ÖеÄÒ»¸öÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¸ÃÎó²î·ºÆðÔÚPLAIN»Ö¸´ÔªÏÂÁî¹ýÂËÆ÷ÖУ¬£¬£¬£¬£¬£¬¸Ã¹ýÂËÆ÷ÊÇΪÐÞ¸´CVE-2025-12762¶øÒýÈëµÄ¡£¡£¡£¡£¡£¸Ã¹ýÂËÆ÷δÄÜ׼ȷʶ±ðÒÔUTF-8×Ö½Ú˳Ðò±ê¼Ç£¨EF BB BF£©»òÆäËûÌØÊâ×Ö½ÚÐòÁпªÍ·µÄSQLÎļþÖеÄÔªÏÂÁî¡£¡£¡£¡£¡£¹ýÂËÆ÷ʹÓõÄhas_meta_commands()º¯Êýͨ¹ýÕýÔò±í´ïʽɨÃèÔʼ×Ö½Ú£¬£¬£¬£¬£¬£¬µ«Î´Äܽ«ÕâЩ×Ö½ÚÊÓΪ¿ÉºöÂÔ£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÔªÏÂÁÈç\\!£©Î´±»¼ì²âµ½¡£¡£¡£¡£¡£µ±pgAdminͨ¹ýpsql fileÏÂÁîŲÓÃSQLÎļþʱ£¬£¬£¬£¬£¬£¬psql»áÈ¥³ýÕâЩ×Ö½Ú²¢Ö´ÐÐÆäÖеÄÏÂÁ£¬£¬£¬£¬£¬´Ó¶ø¿ÉÄܵ¼ÖÂÔ¶³ÌÏÂÁîÖ´ÐС£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
pgAdmin 4 < 9.11
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://github.com/pgadmin-org/pgadmin4/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ